--- title: "๐Ÿ›ก๏ธ Ring2All SBC (Session Border Controller) Deployment Guide" description: "Step-by-step installation and deployment guide for Ring2All SBC (Kamailio 6.1, RTPEngine 12.5, WireGuard Mesh) on Debian 13" --- > Complete step-by-step guide for installing and configuring **Ring2All SBC** on Debian 13 (Trixie), shielding your core telephony cluster with perimeter security, NAT traversal, and encrypted WireGuard mesh. --- ## ๐Ÿ›๏ธ Architecture Overview The **Ring2All SBC (Session Border Controller)** serves as the hardened security perimeter between untrusted public networks (internet subscribers, remote softphones, PSTN carrier trunks) and your private core telephony cluster (Ring2All PBX nodes). ```mermaid flowchart TB subgraph PublicInternet["Public Internet & Carrier Networks"] Subscribers["Remote SIP & WebRTC Clients
(Hardphones, Softphones, Mobile Apps)"] Carriers["Upstream PSTN Carrier Trunks
(Inbound DIDs & Outbound Termination)"] end subgraph SBCPerimeter["Ring2All SBC Gateway (Public IP: 203.0.113.10)"] Firewall["nftables + Pike Anti-Flood Shield"] Kamailio["Kamailio 6.1+ SIP Signaling Engine
(Dispatcher Load Balancing, LCR, Topology Hiding)"] RTPEngine["Sipwise RTPEngine 12.5+ Media Relay
(NAT Traversal, SRTP-to-RTP Transcoding)"] SbcApi["SBC REST API (Fastify 5 :3003)"] SbcWeb["Nginx Reverse Proxy & Admin Web UI (:443)"] WGGateway["WireGuard Mesh Hub (wg0: 10.9.0.1)"] end subgraph PrivateCore["Private Core Network (Zero Public IP Exposure)"] direction TB FS1["Ring2All PBX Node 01
(wg0: 10.9.0.2 / LAN: 192.168.10.41)"] FS2["Ring2All PBX Node 02
(wg0: 10.9.0.3 / LAN: 192.168.10.42)"] BSS["Ring2All BSS (Real-Time OCS Engine)
(LAN: 192.168.10.50)"] end Subscribers -->|Public SIP :5060 / :5061| Firewall Carriers -->|Public SIP :5060| Firewall Subscribers -.->|Public Audio RTP 16384-32768| RTPEngine Carriers -.->|Public Audio RTP 16384-32768| RTPEngine Firewall --> Kamailio Kamailio <--> RTPEngine Kamailio <--> SbcApi SbcWeb <--> SbcApi Kamailio <-->|Encrypted SIP via wg0| WGGateway WGGateway <==|Encrypted WireGuard Mesh (UDP 51820)|==> FS1 WGGateway <==|Encrypted WireGuard Mesh (UDP 51820)|==> FS2 Kamailio <-->|Sub-millisecond OCS Auth| BSS ``` ### Core Responsibilities: 1. **Topology Hiding & Complete Shielding**: Internal FreeSWITCH PBX nodes have **zero public IP exposure**. They sit safely in private subnets, reachable only via encrypted WireGuard tunnels (`10.9.0.0/24`). 2. **High-Performance Media Relay (RTPEngine 12.5+)**: Seamlessly traverses aggressive symmetric NATs, bridges WebRTC (DTLS-SRTP) with legacy carrier RTP, and handles audio streams without CPU overhead. 3. **Perimeter Defense (Pike & nftables)**: Identifies and bans SIP brute-force scanners, floods, and malformed packets in real time. 4. **Dispatcher Load Balancing & LCR**: Evenly distributes SIP calls across the PBX cluster using round-robin or hash-based dispatchers with active SIP OPTIONS health-checks. --- ## ๐Ÿ–ฅ๏ธ System Requirements | Specification | Minimum | Recommended | High Volume / Carrier | | :--- | :--- | :--- | :--- | | **Operating System** | Debian 13 (Trixie) 64-bit | Debian 13 (Trixie) 64-bit | Debian 13 (Trixie) 64-bit | | **CPU** | 4 vCPU | 8 vCPU | 16+ vCPU | | **RAM** | 8 GB | 16 GB | 32 GB | | **Storage** | 80 GB SSD | 160 GB NVMe | 300+ GB NVMe | | **Network Interfaces** | 1 Public IPv4 + 1 Private LAN | 1 Public IPv4 + 1 Private LAN | 10 Gbps redundant NICs | | **Concurrent Calls** | ~500 | ~2,500 | ~10,000+ | --- ## โšก Option 1: Automated One-Touch Installation (Recommended) Ring2All provides an automated one-touch installer that provisions Kamailio 6.1, RTPEngine 12.5, PostgreSQL 17, WireGuard VPN, Nginx reverse proxies, and the SBC management API in a single run. Execute the following command as `root` on your clean Debian 13 server: ```bash wget -O- https://repo.softswitchone.com/apt/install-sbc.sh | bash ``` ### What the Automated Script Configures: 1. Installs base utilities (`curl`, `gnupg2`, `openssl`, `nginx`, `postgresql`, `wireguard`, `fail2ban`, `nftables`). 2. Registers the official Node.js 22 LTS runtime. 3. Installs Kamailio 6.1+ (`kamailio`, `kamailio-postgres-modules`, `kamailio-tls-modules`, `kamailio-websocket-modules`, `kamcli`). 4. Bootstraps the `kamailio` database schema and sets up default domains. 5. Installs the unified `softswitch-sbc` package from the Ring2All repository. 6. Deploys the Fastify-based REST API service (`sbc-api.service`) listening on loopback port `3003`. 7. Configures Nginx virtual host at `/etc/nginx/sites-available/softswitch-sbc` with TLS and WebSocket proxies. 8. Initializes the WireGuard VPN hub interface (`wg0` on `10.9.0.1/24`, UDP port `51820`). 9. Deploys secure `nftables` firewall rules protecting administrative ports while opening SIP and media ports. --- ## ๐Ÿ› ๏ธ Option 2: Step-by-Step Manual Installation If your infrastructure requires fine-grained control, follow this manual step-by-step process. ### Step 1: System Packages & Repositories ```bash # Update and install base tools apt-get update && apt-get install -y curl wget gnupg2 openssl nginx unixodbc odbc-postgresql fail2ban nftables wireguard # Setup Node.js 22 LTS curl -fsSL https://deb.nodesource.com/setup_22.x | bash - apt-get install -y nodejs build-essential # Add Ring2All Official Repository curl -fsSL https://repo.softswitchone.com/apt/setup_repo | bash apt-get update ``` ### Step 2: Database Initialization ```bash apt-get install -y postgresql-17 # Create SBC administrative database and user sudo -u postgres psql << 'EOF' CREATE DATABASE sbc_admin; CREATE USER sbc_user WITH ENCRYPTED PASSWORD 'ChangeMeSecurely123!'; GRANT ALL PRIVILEGES ON DATABASE sbc_admin TO sbc_user; ALTER DATABASE sbc_admin OWNER TO sbc_user; EOF ``` ### Step 3: Install Kamailio 6.1 & RTPEngine ```bash # Install Kamailio core and modules apt-get install -y kamailio kamailio-postgres-modules kamailio-tls-modules \ kamailio-websocket-modules kamailio-json-modules kamailio-presence-modules kamcli # Install Sipwise RTPEngine apt-get install -y rtpengine rtpengine-daemon rtpengine-iptables ``` Initialize the Kamailio PostgreSQL schema: ```bash kamdbctl create # Enter your PostgreSQL credentials when prompted to initialize 'kamailio' database. ``` ### Step 4: Install Ring2All SBC Core Package ```bash apt-get install -y -o Dpkg::Options::="--force-overwrite" softswitch-sbc ``` This installs: - `/var/www/softswitch-sbc/api` (SBC Management REST API) - `/var/www/softswitch-sbc/web` (React Administrative Web Console) - `/etc/softswitch/sbc-api.env` (Environment variables) - `/etc/systemd/system/sbc-api.service` Enable and start the API service: ```bash systemctl daemon-reload systemctl enable --now sbc-api systemctl status sbc-api ``` ### Step 5: Nginx Reverse Proxy Configuration Verify `/etc/nginx/sites-available/softswitch-sbc`: ```nginx server { listen 80; server_name sbc.example.com; return 301 https://$host$request_uri; } server { listen 443 ssl http2; server_name sbc.example.com; ssl_certificate /etc/ssl/certs/softswitch-sbc.crt; ssl_certificate_key /etc/ssl/private/softswitch-sbc.key; # Static Web UI root /var/www/softswitch-sbc/web; index index.html; location / { try_files $uri $uri/ /index.html; } # SBC REST API location /api/ { proxy_pass http://127.0.0.1:3003/; proxy_http_version 1.1; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; } # Real-Time WebSocket Telemetry location /ws { proxy_pass http://127.0.0.1:3003/ws; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_set_header Host $host; proxy_read_timeout 86400; } } ``` Enable and reload: ```bash ln -sf /etc/nginx/sites-available/softswitch-sbc /etc/nginx/sites-enabled/ nginx -t && systemctl reload nginx ``` --- ## ๐Ÿ”’ Connecting Core Telephony via WireGuard Mesh In production multi-datacenter environments, your FreeSWITCH PBX nodes must **never be directly exposed to the public internet**. Instead, they connect to Ring2All SBC via an encrypted WireGuard VPN mesh. ``` โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ” โ”‚ RING2ALL SBC (Server Hub) โ”‚ โ”‚ Public IP: 203.0.113.10 โ”‚ WireGuard IP: 10.9.0.1 โ”‚ โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ โ”‚ ๐Ÿ”’ WireGuard Transit (UDP 51820) โ”‚ โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ” โ”‚ RING2ALL PBX NODE (Client Spoke) โ”‚ โ”‚ LAN Only: 192.168.10.41 โ”‚ WireGuard IP: 10.9.0.2 โ”‚ โ”‚ FreeSWITCH bound to: local_ip_v4 = 10.9.0.2 โ”‚ โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ ``` ### Method A: Automated via Ring2All SBC Web UI (Recommended) 1. Log in to the SBC Web Console (`https://sbc.example.com`). 2. Navigate to **Network > WireGuard > Peers** and click **+ Add Peer**: - **Peer Name**: `PBX-Node-01` - **Assigned IP**: `10.9.0.2/32` - **Allowed IPs**: `10.9.0.2/32` 3. Click **Generate Keys & Configuration**. 4. Download or copy the generated client configuration snippet. 5. On the FreeSWITCH PBX node, paste the content into `/etc/wireguard/wg0.conf`: ```bash apt-get install -y wireguard nano /etc/wireguard/wg0.conf systemctl enable --now wg-quick@wg0 ``` 6. Verify tunnel connectivity from the PBX node: ```bash ping 10.9.0.1 ``` ### Method B: Manual WireGuard Server Configuration On the Ring2All SBC server, `/etc/wireguard/wg0.conf` should look like this: ```ini [Interface] Address = 10.9.0.1/24 ListenPort = 51820 PrivateKey = PostUp = nft add rule inet filter input iifname "wg0" accept PostDown = nft delete rule inet filter input iifname "wg0" accept # PBX Node 01 [Peer] PublicKey = AllowedIPs = 10.9.0.2/32 # PBX Node 02 [Peer] PublicKey = AllowedIPs = 10.9.0.3/32 ``` Restart WireGuard: ```bash systemctl restart wg-quick@wg0 wg show ``` ### WireGuard Audio Performance & Capacity WireGuard executes as an in-kernel module (`wireguard.ko`) utilizing modern ChaCha20-Poly1305 cryptography. It delivers **3 to 5+ Gbps throughput** with near-zero CPU footprint: - 1,000 simultaneous G.711 PCMU calls require only **~80 Mbps** and ~50,000 pps. - WireGuard introduces **< 0.1 ms latency**, completely undetectable in voice audio quality. --- ## ๐ŸŒ DNS & Cloudflare Architecture (Crucial) When configuring DNS for Ring2All SBC, keep in mind that **Cloudflare standard proxy (Orange Cloud โ˜๏ธ๐Ÿงก) supports ONLY HTTP/HTTPS traffic. Cloudflare DOES NOT proxy UDP SIP traffic on port 5060**. ### 1. SIP Signaling DNS Records (Mandatory Grey Cloud โ˜๏ธ๐Ÿฉถ) For SIP registration and carrier trunking, you must create a DNS record with the **Cloudflare proxy disabled** (Grey Cloud โ˜๏ธ๐Ÿฉถ) pointing directly to the SBC public IP: | Type | Name | Content | Proxy Status | Purpose | | :--- | :--- | :--- | :--- | :--- | | **A** | `sbc.example.com` | `203.0.113.10` | **DNS Only (Grey Cloud โ˜๏ธ๐Ÿฉถ)** | SIP UDP/TCP Signaling | | **A** | `sip.example.com` | `203.0.113.10` | **DNS Only (Grey Cloud โ˜๏ธ๐Ÿฉถ)** | Hardphone Registrar | ### 2. SIP Auto-Discovery via SRV Records (RFC 3263) To enable zero-touch provisioning and allow phones to discover the SBC without typing port numbers: ```dns _sip._udp.example.com. IN SRV 10 50 5060 sbc.example.com. _sips._tcp.example.com. IN SRV 10 50 5061 sbc.example.com. ``` ### 3. Web Admin Console DNS Records (Orange Cloud โ˜๏ธ๐Ÿงก) The web administration interface can safely use Cloudflare's CDN and WAF (Orange Cloud โ˜๏ธ๐Ÿงก): | Type | Name | Content | Proxy Status | Purpose | | :--- | :--- | :--- | :--- | :--- | | **CNAME** | `sbc-admin.example.com` | `sbc.example.com` | **Proxied (Orange Cloud โ˜๏ธ๐Ÿงก)** | Web Dashboard & WAF | --- ## ๐Ÿ” Verification & Health Checks Run these commands to verify that Ring2All SBC is operating correctly: ### 1. Service Status ```bash systemctl status kamailio systemctl status rtpengine systemctl status sbc-api systemctl status nginx systemctl status wg-quick@wg0 ``` ### 2. Local API Health Check ```bash curl -s http://127.0.0.1:3003/health # Expected: {"status":"ok","service":"sbc-api","version":"1.0.0"} ``` ### 3. Active Port Listeners ```bash ss -ulnp | grep -E '5060|51820' # Expected: Kamailio listening on 0.0.0.0:5060 and 10.9.0.1:5060; WireGuard on 0.0.0.0:51820 ``` ### 4. Kamailio Runtime Inspection ```bash # Check loaded modules kamcmd system.listMethods # Check dispatcher status (PBX cluster nodes) kamcmd dispatcher.list # Inspect active RTPEngine media sessions rtpengine-ctl list sessions ``` --- ## ๐Ÿ”ง Production Troubleshooting ### 1. Phones fail to register with "Request Timeout (408)" - **Cause**: DNS is pointing through Cloudflare Orange Cloud (which drops UDP port 5060) or `nftables` is dropping inbound SIP packets. - **Solution**: Set DNS record to **Grey Cloud (DNS Only)** in Cloudflare. Check firewall rules: ```bash nft list ruleset | grep 5060 ``` ### 2. One-Way Audio on Calls Traversing SBC - **Cause**: RTPEngine is advertising an internal IP instead of the public IP in SDP headers. - **Solution**: Verify `/etc/rtpengine/rtpengine.conf` interface configuration: ```ini interface = external/203.0.113.10;internal/10.9.0.1 ``` Ensure RTP port range `16384-32768/udp` is permitted through the cloud security group. --- ## ๐Ÿš€ Next Steps - **[Web Cluster & Load Balancing Guide](web-cluster-load-balancing.md)**: Scale your frontend interfaces. - **[Distributed PBX Cluster Guide](distributed-cluster.md)**: Scale out N+1 FreeSWITCH telephony nodes behind this SBC. - **[Ring2All BSS Deployment](bss-deployment.md)**: Connect carrier billing, OCS rating, and customer self-care portals.